High-performance open-source security scanner combining SAST, SCA, Secret Detection, and IaC analysis, built for developers and CI/CD pipelines, using AI for recommendation!
-
Updated
Jun 30, 2026 - Go
High-performance open-source security scanner combining SAST, SCA, Secret Detection, and IaC analysis, built for developers and CI/CD pipelines, using AI for recommendation!
Curated catalog of generally useful kpt functions
TrendAI Vision One Container Security Scan Action
Static analysis from configs → Kubernetes NetworkPolicies in seconds
Managing GitHub Advanced Security (GHAS) Controls at Scale
A complete DevSecOps CI/CD automation pipeline for a Node.js application using GitHub Actions, Docker, Trivy security scanning, and Kubernetes (Minikube), implementing shift-left security and cloud-native deployment practices.
Advanced Conftest GitHub Action for Terraform, Kubernetes, Helm & Dockerfile policy scanning with SARIF, GitHub Security, Slack, Teams and Google Chat notifications.
Pipeline DevSecOps experimental para TCC, medindo o impacto de SAST, SCA e DAST no lead time de CI/CD com FastAPI, Docker, Kubernetes, GitHub Actions e SonarQube.
Workflow Templates for SAST with semgrep, SCA with Trivy, Malware Detection with Depx and Supply Chain attack Mitigation with Custom Age Checks
Servidor LSP para análise estática e conformidade contínua com a LGPD em pipelines DevSecOps (Compliance as Code).
Catch IaC security misconfigurations before production. 100+ rules across Terraform, CloudFormation & Ansible. 9 compliance frameworks.
Pre-cloud web application security assessment including vulnerability analysis, remediation, and cloud security controls.
Enterprise-style DevSecOps CI/CD pipeline demo using GitHub Actions, Semgrep, CodeQL, TruffleHog, pip-audit, and pre-commit.
Enterprise DevSecOps pipeline: GitHub Actions, Terraform, container security scanning, SAST/DAST, policy-as-code, and automated compliance validation
End-to-end DevSecOps CI/CD pipeline integrating SAST, SCA, Secrets Scanning, Container Security, and DAST with automated security gates and deployment blocking using GitHub Actions.
A production-style DevSecOps CI/CD pipeline demonstrating shift-left security with open-source tools. It performs SAST, secrets detection, dependency and container scanning, SBOM generation, and image signing before deploying to Kubernetes. The pipeline can run locally or via GitHub Actions and generates security reports for validation.
CI/CD compliance gate for Australian ISM and Essential Eight — checks K8s, Docker, and IaC via OPA/Rego policies
Git hooks for improving developer experience and security
deliver SAST results to gitlab merge request discussions https://github.com/jonny64/sarif2gl/wiki https://npmjs.com/package/sarif2gl
Pipeline CI/CD DevSecOps pour Terraform : linting, analyse de sécurité (Trivy), plan automatique en PR et apply avec validation humaine (Shift-Left Security).
Add a description, image, and links to the shift-left-security topic page so that developers can more easily learn about it.
To associate your repository with the shift-left-security topic, visit your repo's landing page and select "manage topics."